apache2-licensed
Backup and migrate Kubernetes resources and persistent volumes.
Velero is an open source tool to safely backup and restore, perform disaster recovery, and migrate Kubernetes cluster resources and persistent volumes.
Related contents:
External Secrets Operator reads information from a third-party service like AWS Secrets Manager and automatically injects the values as Kubernetes Secrets.
Related contents:
- (Almost) Every infrastructure decision I endorse or regret after 4 years running infrastructure at a startup @ Jack's home on the web.
- How Maintainer Burnout Is Causing a Kubernetes Security Disaster @ The New Stack.
- GitOps architecture, patterns and anti-patterns @ Platform Engineering.
- Discover the External Secret Operator (ESO) OVHcloud Provider to manage your Kubernetes secrets 🎉 @ OVHcloud.
Power of Kubernetes, Simplicity of Heroku. Making Kubernetes as easy as Heroku
Canine is a Kubernetes platform that makes it easy to deploy and manage your applications.
Virtual Kubernetes and Multi-Tenancy.
Create fully functional virtual Kubernetes clusters - Each vcluster runs inside a namespace of the underlying k8s cluster. It's cheaper than creating separate full-blown clusters and it offers better multi-tenancy and isolation than regular namespaces.
Virtual clusters are fully functional Kubernetes clusters nested inside a physical host cluster providing better isolation and flexibility to support multi-tenancy. Multiple teams can operate independently within the same physical infrastructure while minimizing conflicts, maximizing autonomy, and reducing costs.
Related contents:
Declarative GitOps CD for Kubernetes. Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.
Related contents:
- How to Build a Multi-Tenancy Internal Developer Platform with GitOps and vCluster @ ITNEXT's Medium.
- Unleashing the Power of ArgoCD by Streamlining Kubernetes Deployments @ sitepoint.
- Using ArgoCD ApplicationSet to deploy to multiple clusters @ ITNEXT's Medium.
- Top 30 Argo CD Anti-Patterns to Avoid When Adopting Gitops @ Container Hub's Medium.
- How Engineers are Automating More with Less: Trends in DevOps Tooling @ DevOps.
- Harnessing GitOps on Linux for Seamless, Git-First Infrastructure Management @ Linux Journal.
- Managing Kubernetes Workloads Using the App of Apps Pattern in ArgoCD-2 @ CNCF.
- Anatomy of a Pull Request Generator @ Codefresh.
- Manage Multi-Cluster Deployments with ArgoCD @ DigitalOcean.
- Behind the scenes: Designing Argo CD in Octopus @ Octopus Deploy.
- ArgoCD diffs at scale @ monday engineering.
- How to scale GitOps in the enterprise: From single cluster to fleet management @ Platform Engineering.
- Argo CD 3.3 Brings Safer GitOps Deletions and Smoother Day‑to‑Day Operations @ InfoQ.
- Introduction to ArgoCD: Getting Started with GitOps @ DevOps Daily.
- How to Implement GitOps on Kubernetes Using Argo CD @ freeCodeCamp.
- GitOps policy-as-code: Securing Kubernetes with Argo CD and Kyverno @ CNCF.
- Security Flaw in Argo CD Can Let Attackers Take Over Kubernetes Clusters @ Cloud Native Now.
Power tools for kubectl. Faster way to switch between clusters and namespaces in kubectl.
kubectx is a tool to switch between contexts (clusters) on kubectl faster. kubens is a tool to switch between Kubernetes namespaces (and configure them for kubectl) easily.
Related contents:
An extremely fast Python package and project manager, written in Rust.
Related contents:
- A year of uv: pros, cons, and should you migrate @ Bite code!.
- uv format: Code Formatting Comes to uv (experimentally!) @ Python Developer Tooling Handbook.
- Episode #660: Reinventing Python tooling with Rust @ Changelog Interviews.
- uv is the best thing to happen to the Python ecosystem in a decade @ Dr. Emily L. Hunt.
- Tame Python Chaos With uv – The Superpower Every AI Engineer Needs @ ShiftMag.
- How uv got so fast @ Andrew Nesbitt.
ImageToolbox is a versatile image editing tool designed for efficient photo manipulation. It allows users to crop, apply filters, edit EXIF data, erase backgrounds, and even convert images to PDFs. Ideal for both photographers and developers, the tool offers a simple interface with powerful capabilities.
Kube Resource Orchestrator. Powerful Abstractions for Kubernetes.
Kube Resource Orchestrator (kro) helps you to define complex multi-resource constructs as reusable components in your applications and systems. It does this by providing a Kubernetes-native, vendor agnostic way to define groupings of Kubernetes resources.
Related contents:
A distributed tracing system.
Zipkin is a distributed tracing system. It helps gather timing data needed to troubleshoot latency problems in service architectures. Features include both the collection and lookup of this data.
If you have a trace ID in a log file, you can jump directly to it. Otherwise, you can query based on attributes such as service, operation name, tags and duration. Some interesting data will be summarized for you, such as the percentage of time spent in a service, and whether or not operations failed.
Related contents:
Cursor for Designers.
The power of Cursor for your own React website. Onlook lets you visually edit your React website and write your changes back to code in real-time.
The open source Cursor for Designers. Design directly in your live React app and publish your changes to code.
Easy, fast, and cheap LLM serving for everyone.
vLLM is a fast and easy-to-use library for LLM inference and serving.
Originally developed in the Sky Computing Lab at UC Berkeley, vLLM has evloved into a community-driven project with contributions from both academia and industry.
Related contents:
- How to serve LLMs with vLLM and OVHcloud AI Deploy @ OVHcloud.
- Episode 616: From Boston to bootc @ Linux Unplugged.
- What is vLLM @ RedHat.
- Faire tourner un LLM localement sur votre ordinateur @ Quoi de neuf les devs ? :fr:.
- Inside vLLM: Anatomy of a High-Throughput LLM Inference System @ Aleksa Gordić blog.
- vLLM : Maîtriser l'Inference Haute Performance pour les LLM @ DevSecOps :fr:.
- Docker Model Runner now supports vLLM on Windows @ Docker.
- Running a self-hosted LLM in Kubernetes with vLLM @ CNCF.
Racket is a general-purpose programming language and an ecosystem for language-oriented programming.
Racket is a flexible, multi-paradigm language from the Lisp family, ideal for language-oriented programming. It supports functional, procedural, and object-oriented paradigms, and features a powerful macro system, robust modules, and extensive libraries. Racket is also widely used in education to teach programming concepts and language design.
Related contents:
Open Source Metrics Engine. Distributed TSDB and Query Engine, Prometheus Sidecar, Metrics Aggregator, and more such as Graphite storage and query engine.
M3 is a Prometheus compatible, easy to adopt metrics engine that provides visibility for some of the world’s largest brands.
Related contents:
Open Source & Cross-Cloud Compliance & Security. Costs saving & Optimization.
Kexa's simple rules (Open Source) make it easy to monitoring and manage alerting of your entire cloud. With various monitoring and alerting options, instant and detailed alerts, easy-to-deploy and low in infrastructure costs, in turns complexity into simplicity.
Related contents:
Authentication, authorization, traceability and auditability for SSH accesses.
A so-called bastion is a machine used as a single entry point by operational teams (such as sysadmins, developers, devops, database admins, etc.) to securely connect to other machines of an infrastructure, usually using ssh.
The bastion provides mechanisms for authentication, authorization, traceability and auditability for the whole infrastructure.
Related contents:
A Framework for Modern CLI Apps in Go. A Commander for modern Go CLI interactions.
Cobra is a library for creating powerful modern CLI applications.
Related contents:
OpenVINO™ is an open-source toolkit for optimizing and deploying AI inference.
OpenVINO is an open-source toolkit for optimizing and deploying deep learning models from cloud to edge. It accelerates deep learning inference across various use cases, such as generative AI, video, audio, and language with models from popular frameworks like PyTorch, TensorFlow, ONNX, and more. Convert and optimize models, and deploy across a mix of Intel® hardware and environments, on-premises and on-device, in the browser or in the cloud.
Low code LLM Apps Builder. Build LLM Apps Easily.
Open source low-code tool for developers to build customized LLM orchestration flow & AI agents.
Related contents:
Fast and lightweight DNS proxy as ad-blocker for local network with many features.
Blocky is a DNS proxy and ad-blocker for the local network written in Go.
Related contents:
SOCI Snapshotter is a containerd snapshotter plugin. It enables standard OCI images to be lazily loaded without requiring a build-time conversion step. "SOCI" is short for "Seekable OCI", and is pronounced "so-CHEE".
Related contents:
A research project to add some brrrrrr to Burp.
"burpference" started as a research idea of offensive agent capabilities and is a fun take on Burp Suite and running inference. The extension is open-source and designed to capture in-scope HTTP requests and responses from Burp's proxy history and ship them to a remote LLM API in JSON format. It's designed with a flexible approach where you can configure custom system prompts, store API keys and select remote hosts from numerous model providers as well as the ability for you to create your own API configuration. The idea is for an LLM to act as an agent in an offensive web application engagement to leverage your skills and surface findings and lingering vulnerabilities. By being able to create your own configuration and model provider allows you to also host models locally via Ollama to prevent potential high inference costs and potential network delays or rate limits.
A Kubernetes web UI that is fully-featured, user-friendly and extensible.
Headlamp was created to blend the traditional feature set of other web UIs/dashboards (i.e., to list and view resources) with added functionality.
Related contents:
The open table format for analytic datasets.
Iceberg is a high-performance format for huge analytic tables. Iceberg brings the reliability and simplicity of SQL tables to big data, while making it possible for engines like Spark, Trino, Flink, Presto, Hive and Impala to safely work with the same tables, at the same time.
Related contents:
- PyIceberg: Current State and Roadmap @ Ju Data Engineering Newsletter.
- The Equality Delete Problem in Apache Iceberg @ Data Engineer Things's Medium.
- How I Saved Millions by Restructuring Iceberg Metadata @ Gautham Gondi's Medium.
- High Throughput Ingestion with Iceberg @ Adobe Tech Blog's Medium.
- Scaling Iceberg Writes with Confidence: A Conflict-Free Distributed Architecture for Fast, Concurrent, Consistent Append-Only Writes @ e6data.
- Postgres Is the Gateway Drug @ Vignesh Ravichandran.
Open-source Headless Browser API.
🚧 Open Source Browser API for AI Agents & Apps. Steel Browser is a batteries-included browser instance that lets you build automate the web without worrying about infrastructure.
Debezium is an open source distributed platform for change data capture. Start it up, point it at your databases, and your apps can start responding to all of the inserts, updates, and deletes that other apps commit to your databases. Debezium is durable and fast, so your apps can respond quickly and never miss an event, even when things go wrong.
Related contents:
- Code first CDC from Postgres to ClickHouse with Debezium, Redpanda, and MooseStack @ Fileonefour (Code-First CDC to ClickHouse with Debezium, Redpanda, and MooseStack @ GitHub).
- Change Data Capture Tools @ Dev Genius' Medium.
- The Equality Delete Problem in Apache Iceberg @ Data Engineer Things' Medium.
- You Gotta Push If You Wanna Pull @ Gunnar Morling.
- Keep your cache always fresh with Debezium! (Current 22) @ SpeakerDeck.
- A Deep Dive Into Ingesting Debezium Events From Kafka With Flink SQL @ Gunnar Morling.
- The challenges of soft delete @ atlas9 blog.
Linux virtual machines, with a focus on running containers.
Lima launches Linux virtual machines with automatic file sharing and port forwarding (similar to WSL2).
Related contents:
Lightweight Kubernetes. Production ready, easy to install, half the memory, all in a binary less than 100 MB.
The certified Kubernetes distribution built for IoT & Edge computing.
Related contents:
Open Adversary Exposure Validation Platform. Formerly OpenBAS (Open Breach and Attack Simulation Platform).
OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests.
Linux virtualization in WebAssembly.
WebVM is a server-less virtual environment running fully client-side in HTML5/WebAssembly. It's designed to be Linux ABI-compatible. It runs an unmodified Debian distribution including many native development toolchains.
WebVM is powered by the CheerpX virtualization engine, and enables safe, sandboxed client-side execution of x86 binaries on any browser. CheerpX includes an x86-to-WebAssembly JIT compiler, a virtual block-based file system, and a Linux syscall emulator.
Related contents:
Process Automation Solutions. Build Durable Workflows with Just a Few Lines of Code.
Developer first, open source, serverless workflow automation platform where you code the business logic and autokitteh takes care of the rest: API integration, scalability, reliability, durability, easy deployment, and monitoring.
Status Page On Demand. ⛑ Automated developer-oriented status page. The automated status page that you deserve.
If your infrastructure went down right now, how long would it take for you to know?
Gatus is a developer-oriented health dashboard that gives you the ability to monitor your services using HTTP, ICMP, TCP, and even DNS queries as well as evaluate the result of said queries by using a list of conditions on values like the status code, the response time, the certificate expiration, the body and many others. The icing on top is that each of these health checks can be paired with alerting via Slack, Teams, PagerDuty, Discord, Twilio and many more.
Related contents:
A command-line tool to get valuable information out of AWS CloudTrail and a general purpose toolbox for working with IAM policies
An enterprise friendly way of detecting and preventing secrets in code.
detect-secrets is an aptly named module for (surprise, surprise) detecting secrets within a code base.
A Git-compatible VCS that is both simple and powerful.
Jujutsu is a powerful version control system for software projects. You use it to get a copy of your code, track changes to the code, and finally publish those changes for others to see and use. It is designed from the ground up to be easy to use—whether you're new or experienced, working on brand new projects alone, or large scale software projects with large histories and teams.
Related contents:
- Jujutsu for everyone.
- Steve's Jujutsu Tutorial.
- Tools Worth Changing To in 2025 @ Matthew Sanabria.
- Episode #77: Fallthrough & Friends @ Changelog & Friends.
- What I've learned from jj @ zerowidth positive lookahead.
- Git experts should try Jujutsu @ pksunkara.
- Jujutsu For Busy Devs @ Madeleine Mortensen.
- Jujutsu (jj) - quand Google réinvente Git en mode ninja @ Korben :fr:.
- Switch to Jujutsu already: a tutorial @ Stavros' Stuff.
- I see a future in jj @ Steve Klabnik.
- Reviewing large changes with Jujutsu @ Ben Gesoff.
- Jujutsu megamerges for fun and profit @ Isaac Corbrey.
- Git Is Not Fine @ Bill Jings.
- Reviewing large changes with Jujutsu @ Ben Gesoff.
- What comes after git @ East River Source Control.
Code signing and transparency for containers and binaries. Signing OCI containers (and other artifacts) using Sigstore! Cosign aims to make signatures invisible infrastructure.
Related contents:
Run your own AI cluster at home with everyday devices 📱💻 🖥️⌚
Forget expensive NVIDIA GPUs, unify your existing devices into one powerful GPU: iPhone, iPad, Android, Mac, Linux, pretty much any device!
Related contents:
Harper is an English grammar checker designed to be just right. I created it after years of dealing with the shortcomings of the competition.
Related contents:
Your entire server infrastructure at your fingertips. Manage all your servers from your local desktop. No remote setup required.
XPipe is a new type of shell connection hub and remote file manager that allows you to access your entire server infrastructure from your local machine. It works on top of your installed command-line programs and does not require any setup on your remote systems. So if you normally use CLI tools like ssh, docker, kubectl, etc. to connect to your servers, you can just use XPipe on top of that.
The Apache® Hadoop® project develops open-source software for reliable, scalable, distributed computing.
The Apache Hadoop software library is a framework that allows for the distributed processing of large data sets across clusters of computers using simple programming models. It is designed to scale up from single servers to thousands of machines, each offering local computation and storage. Rather than rely on hardware to deliver high-availability, the library itself is designed to detect and handle failures at the application layer, so delivering a highly-available service on top of a cluster of computers, each of which may be prone to failures.
Related contents:
Gleam is a friendly language for building type-safe systems that scale!
Related contents:
Global payment orchestrator. Global Payments Switch. Fast. Reliable. Affordable.
Full stack payment infrastructure solution to embrace diversity, reduce payment friction and manage compliance. An open source payments switch written in Rust to make payments fast, reliable and affordable.
Giving Kubernetes Superpowers to everyone.
k8sgpt is a tool for scanning your Kubernetes clusters, diagnosing, and triaging issues in simple English. It has SRE experience codified into its analyzers and helps to pull out the most relevant information to enrich it with AI.
Related contents:
Kubernetes Event-driven Autoscaling.
KEDA is a Kubernetes-based Event Driven Autoscaling component. It provides event driven scale for any container running in Kubernetes
Related contents:
An open source multi-tool for exploring and publishing data.
Datasette is a tool for exploring and publishing data. It helps people take data of any shape, analyze and explore it, and publish it as an interactive website and accompanying API.
Embeddable Postgres. Run a full Postgres database locally in WASM with reactivity and live sync. Lightweight WASM Postgres with real-time, reactive bindings.
PGlite is a WASM Postgres build packaged into a TypeScript client library that enables you to run Postgres in the browser, Node.js, Bun and Deno, with no need to install any other dependencies. It is only 3mb gzipped and has support for many Postgres extensions, including pgvector.
Related contents:
Source Available Reinvented Kafka. 10x Cost Efficiency.
AutoMQ is a cloud-first alternative to Kafka by decoupling durability to S3 and EBS. 10x cost-effective. Autoscale in seconds. Single-digit ms latency.
AutoMQ is a stateless Kafka on S3. 10x Cost-Effective. No Cross-AZ Traffic Cost. Autoscale in seconds. Single-digit ms latency. Multi-AZ Availability.
Related contents:
The open source AI code editor.
Void is an open source Cursor alternative. Write code with the best AI tools, retain full control over your data, and access powerful AI features.
An embedded database built on object storage.
Unlike traditional LSM-tree storage engines, SlateDB writes data to object storage to provide bottomless storage capacity, high durability, and easy replication.
SlateDB is an embedded storage engine built as a log-structured merge-tree. Unlike traditional LSM-tree storage engines, SlateDB writes data to object storage (S3, GCS, ABS, MinIO, Tigris, and so on). Leveraging object storage allows SlateDB to provide bottomless storage capacity, high durability, and easy replication. The trade-off is that object storage has a higher latency and higher API cost than local disk.
Related contents:
The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis.
CyberChef is a simple, intuitive web app for carrying out all manner of "cyber" operations within a web browser. These operations include simple encoding like XOR and Base64, more complex encryption like AES, DES and Blowfish, creating binary and hexdumps, compression and decompression of data, calculating hashes and checksums, IPv6 and X.509 parsing, changing character encodings, and much more.
Related contents:
Hexagonal hierarchical geospatial indexing system.
H3 is a geospatial indexing system using a hexagonal grid that can be (approximately) subdivided into finer and finer hexagonal grids, combining the benefits of a hexagonal grid with S2's hierarchical subdivisions.
Related contents:
Convert your Docker Compose file to Kubernetes or OpenShift.
Kompose is a conversion tool for Docker Compose to container orchestrators such as Kubernetes (or OpenShift).
Related contents:
Sigstore is an open source project for improving software supply chain security. The Sigstore framework and tooling empowers software developers and consumers to securely sign and verify software artifacts such as release files, container images, binaries, software bills of materials (SBOMs), and more. Signatures are generated with ephemeral signing keys so there’s no need to manage keys. Signing events are recorded in a tamper-resistant public log so software developers can audit signing events.
Related contents:
- Streamline security with keyless signing and verification in GitLab @ GitLab.
- Annotate container images with build provenance using Cosign in GitLab CI/CD @ GitLab.
- Episode #497: sécurisation de la chaîne d’approvisionnement logicielle (software supply chain) @ NoLimitSecu :fr:.
- Blueprinting Security in CI/CD: Building Trust Through Open Source @ CD Foundation.
The realtime client-side database.
Instant is a client-side database that makes it easy to build real-time and collaborative apps like Notion or Figma.
Related contents:
Cloud-native high-performance edge/middle/service proxy. Envoy is an open source edge and service proxy, designed for cloud-native applications.
Policy-based control for cloud native environments. Flexible, fine-grained control for administrators across the stack.
Open Policy Agent (OPA) is an open source, general-purpose policy engine that enables unified, context-aware policy enforcement across the entire stack.
Related contents:
- Guardrails for Your Cloud: A Simple Guide to OPA and Terraform @ Sami Banerjee's Medium.
- Getting Open Policy Agent Up and Running @ The New Stack.
- Simplify Kubernetes Security With Kyverno and OPA Gatekeeper @ The New Stack.
- Automating policy enforcements for infrastructure using Open Policy Agent (OPA) in Terraform — Part 1 @ Ashay Maheshwari's Medium.
- Terraform governing with OPA @ DevOpsOnTheTrail.
- Blueprinting Security in CI/CD: Building Trust Through Open Source @ CD Foundation.
- From Kubernetes Gatekeeper to Full-Stack Governance with OPA @ Pulumi.
- Governing infrastructure as code using pattern-based policy as code @ AWS Security Blog.
A Knowledge Graph Brain for World Wide Web Surfers. A Customizable AI Research Agent just like NotebookLM or Perplexity, but connected to external sources such as search engines (Tavily, LinkUp), Slack, Linear, Notion, YouTube, GitHub and more.
SurfSense is like a Knowledge Graph Brain 🧠 for anything you see (Social Media Chats, Calender Invites, Important Mails, Tutorials, Recipies and anything ) on the World Wide Web.
NetBox - The Premier Network Source of Truth.
NetBox is the source of truth for everything on your network, from physical components like power systems and cabling to virtual assets like IP addresses and VLANs. Network automation and observability tools depend on NetBox’s authoritative data to roll out configurations, monitor changes, and accelerate operations across the enterprise.
Open Source Declarative Data Orchestration. Event-Driven Declarative Orchestrator.
Infinitely scalable, event-driven, language-agnostic orchestration and scheduling platform to manage millions of workflows declaratively in code.
Kestra is a universal open-source orchestrator that makes both scheduled and event-driven workflows easy. By bringing Infrastructure as Code best practices to data, process, and microservice orchestration, you can build reliable workflows and manage them with confidence.
Related contents:
concurrent, cache-efficient, and Dockerfile-agnostic builder toolkit.
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner.
Related contents: